
The takeaway in 30 seconds: The current SEC has pulled back from pursuing recordkeeping failures as standalone enforcement cases, but that is a change in enforcement focus, not a relaxation of the standard. The question has shifted from “Did you retain everything?” to “Can you prove what you did?” In 2026, records are evaluated as the evidence base that makes every other compliance obligation defensible. A compliance program that does the right things without producing retrievable proof of those actions remains one of the most common, and most correctable, sources of exam findings.
Recordkeeping has been a named SEC examination priority for several consecutive years. In 2026 it remains one, but the expectation underneath it has shifted in a way most RIAs haven’t fully absorbed.
Here’s the data that defines the shift. Between late 2021 and 2024, the prior Commission brought 95 enforcement actions against firms for books-and-records violations, specifically the failure to maintain off-channel communications, resulting in approximately $2.3 billion in penalties, according to the SEC’s FY2025 enforcement results. Those were standalone cases. The violation was the missing record itself, and the penalty was calibrated to the volume and duration of the deficiency.
The current Commission has explicitly repudiated that approach. In its FY2025 enforcement results, it stated that those 95 enforcement actions identified no direct investor harm and produced no measurable investor benefit, characterizing them as a misallocation of resources and an example of prioritizing case volume over investor protection.
The misreading of that statement is that recordkeeping enforcement relaxed. It didn’t. The target changed.
Recordkeeping in 2026 is evaluated as evidentiary infrastructure: the foundation that makes every other aspect of the compliance program defensible or indefensible when an examiner begins asking questions about fiduciary conduct, conflict disclosures, and supervision. Those are now the primary examination focus. Your records are what determine whether you can defend your conduct in those areas. That’s a higher bar than retention-for-its-own-sake, not a lower one.
The Current Standard: Retrievable, Not Just Retained
Rule 204-2 has always required records to be retained for five years, with the first two years easily accessible. What changed is how “easily accessible” gets evaluated in practice.
In prior exam cycles, a firm could satisfy the standard by demonstrating records existed and could eventually be produced. Examiners were once relatively forgiving about production timelines. That is no longer the operating reality. Risk-based examinations, which now represent the majority of SEC exam activity, begin with targeted document requests tied to specific areas of focus and expect prompt, organized production.
The practical implication is the gap most firms don’t see until they’re in it: a firm can retain everything and still fail the accessibility standard. Records scattered across a shared drive, an email archive, a compliance platform, and a folder on the CCO’s desktop are not missing. They are simply not producible within the timeframe an examiner expects. The failure is not retention. It is retrieval..
The infrastructure that meets the 2026 standard has three characteristics:
- Centralized storage in one searchable system, not distributed across tools that don’t talk to each other.
- Indexing that maps to Rule 204-2 categories, the way examiners request records, rather than to internal naming conventions.
- Retrieval measured in hours, not days. If producing a record requires manual aggregation across systems, the program isn’t audit-ready regardless of how complete the underlying records are.
Written Communications: Why the Scope Didn’t Shrink
The off-channel enforcement wave established that business communications on personal devices and unapproved platforms carry the same retention obligation as formal correspondence. The current Commission stepped back from pursuing those failures as standalone cases, but that reflects a shift in what the SEC is looking for, not a relaxation of what it expects. The standard has not changed. The expectation remains that firms can produce complete, accurate, and retrievable records that support their compliance activities when examined.
In 2026, examiners care about written communications because they’re the evidence trail for fiduciary conduct. Consider the sequence: a client alleges an advisor recommended a position without disclosing a conflict. The examiner wants to know what the advisor actually said in the weeks around that recommendation.The text messages, the LinkedIn thread, the WhatsApp exchange the client preferred, these aren’t primarily a recordkeeping question anymore. They’re the documentary record of whether the advice was consistent with the firm’s fiduciary obligations.
That reframes the obligation. Capturing communications across every channel advisors actually use, including text, social platforms, and messaging apps, isn’t about avoiding a standalone recordkeeping case that the SEC is now less likely to bring. It’s about having the evidence to defend a conduct question if one arises. The firms that built capture infrastructure over the past three years aren’t over-complying. They’re the ones whose documentation will hold up when an examiner wants to see what was actually communicated, not what the formal correspondence suggests.
Marketing Materials and Performance Documentation
The Marketing Rule elevated marketing recordkeeping from a secondary concern to a primary exam focus. In 2026, examiners don’t just confirm that materials were reviewed, they examine the documentation structure around the review.
For each piece of marketing content, the current standard expects a complete chain:
- The original submitted version
- Every revision, with the reviewer’s annotations and questions
- The resubmitted version, if applicable
- The approval, with timestamp and approver identity
- The final version, stored so it can be compared against what was actually published
Performance claims require an additional layer: the supporting data behind every figure, including net and gross calculations, composite construction methodology, and the time period represented, retained alongside the materials that display it. When an examiner asks how a specific return was calculated, the answer has to come from a retained document, not a reconstruction.
The failure mode that generates findings here isn’t inadequate review. It’s informal review. The content was reviewed carefully, in a comment thread, a reply-all email, or a verbal exchange that was never captured. The content is compliant. The proof of the review isn’t. Under the Marketing Rule, that distinction is the finding..
Code of Ethics Records: What “Complete” Actually Means
Rule 204-2(a)(12) requires retention of code-of-ethics records, including each access-person report, records of any decision approving an acquisition in an IPO or limited offering, and records of any violation and the action taken.
Examiners in 2026 look past whether annual acknowledgments were collected. They want acknowledgments tied to a specific cycle, a specific version of the code, and a specific employee, not a generic “I have read the code of ethics” statement with no supporting context.
Access-person reports are the more demanding category. Every employee with access to client portfolio information must report initial holdings, annual holdings, and every reportable personal securities transaction. Those reports need to be retained and organized by employee and date, and the firm must demonstrate it compared them against client holdings and restricted lists, with the comparison and its outcome documented.
The failure mode here is rarely missing reports. It’s reports that were collected but never organized in a way that demonstrates the firm actually reviewed them against the required benchmarks. Collection isn’t supervision. The documented comparison is.
Vendor and Third-Party Documentation
The Reg S-P amendments and SEC cybersecurity rules moved vendor documentation from a secondary category to a primary one. Examiners evaluating third-party risk management in 2026 look for a documentation structure most firms have only partially built.
There are three layers, and firms tend to have the first while missing the second and third:
- Initial due diligence: the questionnaire sent, the response received, the firm’s evaluation, and a documented conclusion that the vendor meets the firm’s standards. Most firms have this.
- Re-review documentation: evidence the firm returned to the vendor on a defined cycle, confirmed the security and data-handling posture remained adequate, and updated its records. This is the layer most firms are missing.
- Breach notification provisions: contract language requiring notification within 72 hours of a confirmed breach, in a signed agreement, not a general terms-of-service clause. The Reg S-P amendments made this explicit, and examiners now look for it as a standard part of the review.
What closes the loop is a vendor oversight log: when each relationship was last reviewed, what was confirmed, and when the next review is scheduled. Not a calendar reminder, but a maintained record that demonstrates ongoing oversight as a practice rather than a one-time onboarding exercise.
The Annual Review as a Documented Deliverable
Rule 206(4)-7 requires an annual review of the adequacy of the firm’s compliance policies and procedures. In 2026, “adequacy” is measured against a more specific standard, whether the program kept pace with regulatory change and business growth, not just whether the review happened.
Three components satisfy the current expectation:
- A formal written deliverable: scope, methodology, findings, and conclusions. Not a checklist marked complete, but a substantive document, dated, signed by the CCO, and retained alongside prior years’ reviews.
- Evidence the review addressed regulatory change: the Marketing Rule, cybersecurity disclosure requirements, Reg S-P amendments, and other developments should appear as documented considerations, with notes on how policies were updated in response.
- A record of follow-through:: any gap identified should have corresponding remediation documentation showing what was done and when.
That third component is the one most firms get wrong, and the reason is worth naming. The gap identification and the fix often happen in the same conversation, and neither gets written down. An annual review that surfaces three deficiencies and has no follow-up record is more damaging under examination than one that found nothing. It tells the examiner the firm identified problems and didn’t treat them as requiring a documented response. That’s a program that monitors itself but doesn’t hold itself accountable, which is a different and worse finding than a program that simply missed something.
The Underlying Expectation
The 2026 standard reduces to one sentence: every compliance activity your firm undertakes should produce a record an examiner can review without your team reconstructing what happened from memory or assembling it from multiple systems under time pressure.
The principle isn’t new. What’s new is how consistently it’s applied in risk-based exams, and how clearly the Commission has signaled that compliance program failures, including inadequate disclosures, insufficient fiduciary analysis, and undocumented supervision, are now the primary focus. Recordkeeping deficiencies in those categories don’t generate standalone cases the way off-channel communications once did. They make the underlying conduct problem harder to defend.
A program whose records are current, organized, and immediately retrievable doesn’t just satisfy the recordkeeping standard. It makes every other obligation more defensible, because the evidence of doing the right thing is always available when it’s needed.
What to Do With This
If you do one thing after reading this, run a retrieval test against the SEC’s typical initial document request.
Pick five record types an examiner would ask for first: marketing review documentation, access-person reports, the most recent annual review, vendor due diligence records, and your written communications archive. Then time how long it takes to produce each one, complete and accurate, in a form you’d hand to an examiner.
- If every record takes under an hour to produce: your infrastructure meets the 2026 standard. Document the test itself as evidence of proactive readiness.
- If some take a day or more, or require pulling from multiple systems: you’ve found your gap. It’s not a retention problem, it’s a centralization and indexing problem, and it’s fixable before an exam rather than during one.
- If you can’t produce one at all: that’s the priority. Reconstruct it now, while you have time and context, not under a document request with the clock running.
The firms that move through exams without a scramble didn’t do more compliance work than everyone else. They built the documentation infrastructure so the proof was created as the work happened, which turns exam prep from a two-week reconstruction into a same-day export.





